Cookie-Bite attack PoC uses Chrome extension to steal session tokens April 22, 2025 A proof-of-concept attack called “Cookie-Bite” uses a browser extension to steal browser session cookies from Azure Entra ID to bypass multi-factor
Phishers abuse Google OAuth to spoof Google in DKIM replay attack April 22, 2025 In a rather clever attack, hackers leveraged a weakness that allowed them to send a fake email that seemed delivered
Microsoft Entra account lockouts caused by user token logging mishap April 22, 2025 Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged
WordPress ad-fraud plugins generated 1.4 billion ad requests per day April 22, 2025 A large-scale ad fraud operation called ‘Scallywag’ is monetizing pirating and URL shortening sites through specially crafted WordPress plugins that